From 23cb5e4ac71c34abbe9aa91718c755d1da07e7bf Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Wed, 7 Jan 2026 16:52:50 +0000 Subject: [PATCH 1/2] chore(deps): bump @modelcontextprotocol/sdk in /mcp-server Bumps [@modelcontextprotocol/sdk](https://github.com/modelcontextprotocol/typescript-sdk) from 1.25.1 to 1.25.2. - [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases) - [Commits](https://github.com/modelcontextprotocol/typescript-sdk/compare/1.25.1...v1.25.2) --- updated-dependencies: - dependency-name: "@modelcontextprotocol/sdk" dependency-version: 1.25.2 dependency-type: direct:production ... Signed-off-by: dependabot[bot] --- mcp-server/package-lock.json | 24 +++++------------------- 1 file changed, 5 insertions(+), 19 deletions(-) diff --git a/mcp-server/package-lock.json b/mcp-server/package-lock.json index 48363f4..c4a0a83 100644 --- a/mcp-server/package-lock.json +++ b/mcp-server/package-lock.json @@ -1,12 +1,12 @@ { "name": "@currents/mcp", - "version": "2.1.1", + "version": "2.1.2", "lockfileVersion": 3, "requires": true, "packages": { "": { "name": "@currents/mcp", - "version": "2.1.1", + "version": "2.1.2", "license": "ISC", "dependencies": { "@modelcontextprotocol/sdk": "^1.18.0", @@ -1013,9 +1013,9 @@ } }, "node_modules/@modelcontextprotocol/sdk": { - "version": "1.25.1", - "resolved": "https://registry.npmjs.org/@modelcontextprotocol/sdk/-/sdk-1.25.1.tgz", - "integrity": "sha512-yO28oVFFC7EBoiKdAn+VqRm+plcfv4v0xp6osG/VsCB0NlPZWi87ajbCZZ8f/RvOFLEu7//rSRmuZZ7lMoe3gQ==", + "version": "1.25.2", + "resolved": "https://registry.npmjs.org/@modelcontextprotocol/sdk/-/sdk-1.25.2.tgz", + "integrity": "sha512-LZFeo4F9M5qOhC/Uc1aQSrBHxMrvxett+9KLHt7OhcExtoiRN9DKgbZffMP/nxjutWDQpfMDfP3nkHI4X9ijww==", "license": "MIT", "dependencies": { "@hono/node-server": "^1.19.7", @@ -4441,20 +4441,6 @@ } } }, - "node_modules/release-it/node_modules/magicast": { - "version": "0.3.5", - "resolved": "https://registry.npmjs.org/magicast/-/magicast-0.3.5.tgz", - "integrity": "sha512-L0WhttDl+2BOsybvEOLK7fW3UA0OQ0IQ2d6Zl2x/a6vVRs3bAY0ECOSHHeL5jD+SbOpOCUEi0y1DgHEn9Qn1AQ==", - "dev": true, - "license": "MIT", - "optional": true, - "peer": true, - "dependencies": { - "@babel/parser": "^7.25.4", - "@babel/types": "^7.25.4", - "source-map-js": "^1.2.0" - } - }, "node_modules/require-from-string": { "version": "2.0.2", "resolved": "https://registry.npmjs.org/require-from-string/-/require-from-string-2.0.2.tgz", From 159532a77effd07151077a48810b8f79fc0b8329 Mon Sep 17 00:00:00 2001 From: miguelangarano Date: Fri, 9 Jan 2026 11:49:55 -0500 Subject: [PATCH 2/2] chore: upgrade model context protocol sdk to fix security issue --- mcp-server/package-lock.json | 16 +++++++++++++++- mcp-server/package.json | 2 +- 2 files changed, 16 insertions(+), 2 deletions(-) diff --git a/mcp-server/package-lock.json b/mcp-server/package-lock.json index c4a0a83..5595cf9 100644 --- a/mcp-server/package-lock.json +++ b/mcp-server/package-lock.json @@ -9,7 +9,7 @@ "version": "2.1.2", "license": "ISC", "dependencies": { - "@modelcontextprotocol/sdk": "^1.18.0", + "@modelcontextprotocol/sdk": "^1.25.2", "commander": "^12.1.0", "pino": "^9.9.5", "pino-pretty": "^13.1.1", @@ -4441,6 +4441,20 @@ } } }, + "node_modules/release-it/node_modules/magicast": { + "version": "0.3.5", + "resolved": "https://registry.npmjs.org/magicast/-/magicast-0.3.5.tgz", + "integrity": "sha512-L0WhttDl+2BOsybvEOLK7fW3UA0OQ0IQ2d6Zl2x/a6vVRs3bAY0ECOSHHeL5jD+SbOpOCUEi0y1DgHEn9Qn1AQ==", + "dev": true, + "license": "MIT", + "optional": true, + "peer": true, + "dependencies": { + "@babel/parser": "^7.25.4", + "@babel/types": "^7.25.4", + "source-map-js": "^1.2.0" + } + }, "node_modules/require-from-string": { "version": "2.0.2", "resolved": "https://registry.npmjs.org/require-from-string/-/require-from-string-2.0.2.tgz", diff --git a/mcp-server/package.json b/mcp-server/package.json index 6ff7771..62ca86b 100644 --- a/mcp-server/package.json +++ b/mcp-server/package.json @@ -23,7 +23,7 @@ "author": "", "license": "ISC", "dependencies": { - "@modelcontextprotocol/sdk": "^1.18.0", + "@modelcontextprotocol/sdk": "^1.25.2", "commander": "^12.1.0", "pino": "^9.9.5", "pino-pretty": "^13.1.1",